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In the Claixaa 



The status of claims in the case is as follows: 



1 1. [Currently amended] A system for a web based trust 

2 model governing delivery of services and programs from a 

3 workflow, enterprise and mail-enabled application server and 

4 platform, comprising: 

5 a connection protocol connecting a \iser client to a 
'6 server site; 

7 download utilities responsive to said connection 

B protocol for downloading said services and programs 

9 from said server site to separate and non-conflicting 

10 execution spaces at said user client; and 



trust assignment user interface dialogs responsive to 
said connection protocol for advising said user of 
risks taken when accepting executable download from 
said server site; and 

said server site responsive to said user accepting said 
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server aite as truated for centrally administering 
secLirity policies for said services and programs 
executing at said user client . 

2. [Original] The system of claim 1^ said connection 
protocol selectively being HTTP or HTTPS, 

3, [Original] The system of claim 1, fxirther comprising: 

a processor for establishing security context, said 
processor including 



a stage 1 processor for determining from said user 
if said server site is to be trusted; and 

a stage 2 processor for establishing whether or 
not the identity of said web site is confirmed and 
determining from said user if processing should 
continue to include installation of programs on 
said client . 



4. [Original] The system of claim 3, further comprising: 



a client download page; 
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a download control element in said download page; 

said processor being activated upon activation of said 
download control element within said download page 
initiating a download process first to establish a 
security context and then to download program 
executable files, 

5- [Original] The system of claim 2, further comprising: 

said download utilities being responsive to an SSL 
connection to said server for activating said dialog to 
advise said user that said server site has been 
verified as being what it represents itself to be and 
to query said user whether code is to be downloaded 
from said server site to said client - 

6. [Original] The system of claim 5, said code being 
custom code. 

7. [Previously amended] The system of claim 5, said 
download utilities being responsive to a connection from 
said client to said server being other than SSL for 
activating said dialog to advise said user that said server 
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5 site has not been verified as being what it represents 

6 itself to be and to query said user whether code is to be 

7 downloaded from said server site to said client. 

1 . 8* [Original] The system of claim 7, said code being 

2 custom code. 

1 9, [Original] The system of claim 1, further comprising: 

2 said download utilities being responsive to user 

3 acceptance of download from said server site of 

4 executable code for downloading said executable code to 

5 said client; 

6 a trace utility for identifying originators of 

7 downloaded code- 

1 10. [Original] The system of claim 9, said trace utility 

2 selectively identifying originators of signed agents through 

3 electronic signature, of custom code traceable to code 

4 vendor through web site relationship, or custom code 

5 directly created by said web site. 

1 11. [Original] The system of claim 1, further comprising: 
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a first trust model for establishing level of traceable 
accountability for a subscription at download time over 
a secure connection protocol ; 

a second trust model for establishing a reduced level 
of traceable accountability, with traceable 
accountability established only for electronically 
signed agents used by said subscription over a 
connection protocol not verified as secure; and 

said dialogs being responsive to said trust models. 

12. [Currently amended] A method for governing delivery of 
services and programs from a workflow, enterprise and mail- 
enabled application server and platform according to a web 
based trust model, con^^rising the steps of; 

establishing a connection protocol between a client and 
a web site; 

responsive to said connection protocol, determining a 
trust level assignable to said web site relative to 
risks taken when accepting executable download from 
said web site; 
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advising a user at said client of said trust level 
assignable with respect to said risks to said web site; 
and 

responsive to user acceptance of said risks and 
accepting said server site as trusted, downloading said 
services and programs from a server site to separate 
and non-conflicting execution spaces at said user 
client and centrally administering, security policies 
for said ser-vices and programs executing at said 
client . 

13. [Original] The method of claim 12, further comprising 
the steps of: 

displaying a download control element in a client 
download page; 

responsive to user selection of said download control 
element or upon schedule, initiating a. download process 
first to establish a sec\arity context and then to 
download program executable files from said server. 
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14. [Original] The method of claim 12, further comprising 
the step of: 

responBive to user acceptance of download from said 
server site of executable code, downloading said 
executable code to said client. 

15. [Original] The method of claim. 14, further comprising 
the step of: 

identifying originators of downloaded code. 

16. [Original] The method of claim 15, further comprising 
the step of 

selectively identifying originators of signed agents 
through electronic signature, of custom code traceable 
to code vendor through web site relationship, or custom 
code directly created by said web site. 

17. [Previously amended] The method of claim 12, further 
comprising the steps of 

establishing a first trust model specifying a level of 
LOT920000011US1 8 S/N 09/596,745 
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4 traceable accoiantabillty for a subscription at download 

5 time over a secure connection protocol; 

6 establishing a second trust model for specifying a 

7 reduced level of traceable accovmtability, with 

8 traceable accountability established only for 

9 electronically signed agents used by said subscription 

10 over a connection protocol not verified as secure; and 

11 said dialogs being responsive to said trust models. 

1 18, [Currently amended] A program storage device readable 

2 by a machine, tangibly embodying a program of instructions 

3 executable by a machine to perform method steps for 

4 governing delivery of services and programs from a workflow, 

5 enterprise and mail-enabled application server and platform 

6 according to a web based trust model, said method steps 

7 comprising: 

8 establishing a connection protocol between a client and 

9 a web site; 

10 responsive to said connection protocol, determining a 

11 trust level assignable to said web site relative to 
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risks taken when accepting executable download from 
said web site; 

advising a user at said client of said trust level 
assignable with respect to said risks to said web site; 
and 

responsive to user acceptance of said risks and 
accepting said server site as trusted, downloading said 
services and programs from a server site to separate 
euid non-conflicting execution spaces at said user 
client and centrally administering security policies 
for said services and programs for central Iv 
determining and control lino services and programs to be 
Qy,ecuted at said client. 

19. [Currently amended] A computer program product 
configured to be operable to govern delivery of services and 
programs from a workflow, enterprise and mail -enabled 
application server and platform according to a web based 
trust model, according to the steps of: 

establishing a connection protocol between a client and 
a web site; 
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8 responsive to said connection protocol, deterrnining a 

9 trust level assignable to said web site relative to 

10 risks taken when accepting executable download from 

11 said web site; 

12 advising a user at said client of said trust level 

13 assignable with respect to said risks to said web site; 

14 and 

15 responsive to user acceptance of said risks and 

16 accepting said server site as trusted, downloading said 

17 services and programs from [ [a] ] said server site to 

18 separate and non-conflicting execution spaces at said 

19 user client and centrally administering firom saA<^ 

2 0 server site security policies for control which said 

21 services and programs shall be executed at said cliQUt. 
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